VLDB 2026 Research / reviewers in the wild / expert
Lidong Zhai
dblp:38/10035
· DBLP profile ↗
13ranked-venue papers
2as first author
6since 2021 · last 2025
0009-0009-6764-2060ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorComputer networks · 1Software engineering, systems software and programming languages · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1Theory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Multi-Leader Multi-Follower Stackelberg Game Based Defense Strategies Optimization for Interdependent SystemsabstractMany critical infrastructures today exhibit complex interdependencies, which facilitate cross system attacks. Therefore, intrusion intent and path prediction for interdependent systems are crucial. This article proposes multi-leader multi-follower Stackelberg game model utilizing attack graphs to depict potential attack paths and defense strategies, aimed at optimizing defense strategies decisions for interdependent systems. To address potential conflicts of interest in collaborative decision-making among multiple defenders, we introduce two game theory algorithm variants that balance individual and collective utility. The experimental results show that game theory based algorithms exhibit significant advantages in both runtime performance and solution quality, due to their mutual adjustment in multiple iterations, which is more in line with the stability requirements of practical applications. Lidong Zhai |
CSCWD | 5 |
| 2025 | Integrating IRT and Knowledge Graphs for the Selection of Cybersecurity TalentabstractIn recent years, the cybersecurity landscape has become increasingly severe, with a significant shortage of skilled professionals in the field. Against this backdrop, cultivating high-quality cybersecurity talent has become an urgent task. This paper proposes an innovative method that integrates Item Response Theory (IRT) and knowledge graphs to address this challenge. The core innovation lies in the fusion of IRT with knowledge graph technology to provide personalized, adaptive assessments. By leveraging cognitive diagnosis theory and adaptive theory, the method assesses participants' cognitive levels while considering factors such as psychological state, professional skills, and cognitive ability. This approach intelligently adjusts the difficulty of questions in real-time based on the participant's performance. Furthermore, the incorporation of knowledge graph technology allows for a deeper analysis of the relationships between different knowledge domains. Based on these comprehensive insights, personalized learning suggestions and strategies are formulated, enabling continuous tracking of talent development. This adaptive method offers a scientific and effective pathway for the cultivation and selection of cybersecurity professionals. Lvyang Zhang, Weihan Yuan, Lidong Zhai |
CSCWD | 5 |
| 2024 | NanoHook: An Efficient System Call Hooking Technique with One-Byte Invasive
Quan Hong, Jiaqi Li 0014, Lidong Zhai |
SETTA | 4 |
| 2024 | Active Defense Research: A New Perspective Integrating Traps and VulnerabilitiesabstractActive defense represents an asymmetric defensive strategy to reverse the imbalance between offense and defense. It primarily utilizes methods such as interference and deception to raise the cost of attacks and proactively identify potential threats. Within this field, active defense technologies leveraging deception tactics are regarded as a game-changer in cyber warfare. However, existing deception-based defense technologies predominantly focus on attack detection and mitigation, neglecting the possibility of fundamentally resolving the issue, namely preventing attacks by deterring potential adversaries. Recognizing vulnerabilities as the core of cyber warfare, this paper applies the concept of trap deception to vulnerabilities, proposing an active defense technique that confuses and deters attackers. This technique is triggered only when vulnerabilities are exploited, so it can detect, prevent, and trace attacks without impacting the program’s operation. This paper elaborates on the defensive philosophy of this technique and describes its implementation strategies. We argue that this approach holds significant promise in deterring attackers effectively, thereby mitigating the offensive-defense imbalance in cybersecurity. Quan Hong, Lvyang Zhang, Lidong Zhai |
TrustCom | 4 |
| 2023 | Assessing the Effectiveness of Deception-Based Cyber Defense with CyberBattleSim
Quan Hong, Xizhong Guo, Pan Xie, Lidong Zhai |
ICDF2C (2) | 5 |
| 2023 | InfinityGauntlet: Expose Smartphone Fingerprint Authentication to Brute-force Attack
Lidong Zhai |
USENIX Security Symposium | 3 |
| 2018 | Botnet homology method based on symbolic approximation algorithm of communication characteristic curveabstractThe IRC botnet is the earliest and most significant botnet group that has a significant impact. Its characteristic is to control multiple zombies hosts through the IRC protocol and constructing command control channels. Relevant research analyzes the large amount of network traffic generated by command interaction between the botnet client and the C&C server. Packet capture traffic monitoring on the network is currently a more effective detection method, but this information does not reflect the essential characteristics of the IRC botnet. The increase in the amount of erroneous judgments has often occurred. To identify whether the botnet control server is a homogenous botnet, dynamic network communication characteristic curves are extracted. For unequal time series, dynamic time warping distance clustering is used to identify the homologous botnets by category, and in order to improve detection. Speed, experiments will use SAX to reduce the dimension of the extracted curve, reducing the time cost without reducing the accuracy. Zhihong Nan, Lichao Zhai, Lidong Zhai, Huiming Liu |
AVSS | 3 |
| 2018 | Research Notes: User Influence in Microblog Based on Interest GraphabstractMicroblog is currently the largest social networking platform in China. In recent years, as a social media, the influence of microblog continues to expand. The users who have large influence play a guiding role in the spread of microblog, and even guide the trends of public opinion. Therefore, we propose an influence analysis method to find microblog users who are with great influence, which is of great significance for the research and mining of microblog. User influence analysis in microblog has great difficulties due to the limited amount of microblog information, quick updates and nonstandard microblog language. First, we use the label propagation algorithm combined with LDA algorithm to divide users by the user interest graph, according to the social relationship of microblog users and the content they generate. Then, depending on different interest areas, an improved PageRank algorithm based on user interaction behavior is proposed to calculate the user’s influence. Experiments on the real datasets show that the proposed method outperforms the traditional algorithms. Lidong Zhai, Chaojian Hu |
Int. J. Softw. Eng. Knowl. Eng. | 1 |
| 2014 | A Game Model for Predicting the Attack Path of APTabstractAs a major threat today, how to defense against APT (advanced persistent attack) effectively becomes a major issue for network security. APT is a combination of past attacks, not a new one. It's different from any one of previous attacks. Predicting the attack path of APT exactly would be a breakthrough for the future defense in Internet of things. Firstly, the paper proposes classifications of attack and defense for game model from the perspective of game theory. Then, we present the OAPG model, which uses attack path of APT as the attacker's strategy. Finally, according to the Nash equilibrium, we compute the optimal attack path for the attacker and best-response strategies for the defender. Xupeng Fang, Lidong Zhai, Zhaopeng Jia, Wenyan Bai |
DASC | 2 |
| 2014 | Location Privacy in Buildings: A 3-Dimensional K-Anonymity ModelabstractPrivacy protection has recently received considerable attention in location-based services. In this paper, we show that most of the existing k-anonymity location cloaking algorithms are concerned only and cannot effectively prevent location-dependent attacks when users' locations have height information. Therefore, adopting the three dimensional location information, we propose a new clique-based cloaking algorithm, called 3d Clique Cloak, to defend against location leaks in indoor environment. The main idea is to expand the MBV (minimum bounding volume) to a three-dimensional space, thus for a user who initiated location services can find k-anonymity cloaking set in the three-dimensional space. The efficiency and effectiveness of the proposed 3d Clique Cloak algorithm are validated by series of carefully designed experiments. Yujia Zhu, Lidong Zhai |
MSN | 2 |
| 2014 | Detection of Android Malicious Apps Based on the Sensitive BehaviorsabstractThe number of malicious applications (apps) targeting the Android system has exploded in recent years. The evolution of malware makes it difficult to detect for static analysis tools. Various behavior-based malware detection techniques to mitigate this problem have been proposed. The drawbacks of the existing approaches are: the behavior features extracted from a single source lead to the low detection accuracy and the detection process is too complex. Especially it is unsuitable for smart phones with limited computing power. In this paper, we extract sensitive behavior features from three sources: API calls, native code dynamic execution, and system calls. We propose a sensitive behavior feature vector for representation multi-source behavior features uniformly. Our sensitive behavior representation is able to automatically describe the low-level OS-specific behaviors and high-level application-specific behaviors of an Android malware. Based on the unified behavior feature representation, w e provide a light weight decision function to differentiate a given application benign or malicious. We tested the effectiveness of our approach against real malware and the results of our experiments show that its detection accuracy up to 96% with acceptable performance overhead. For a given threshold t (t=9), we can detect the advanced malware family effectively. Daiyong Quan, Lidong Zhai, Fan Yang 0049 |
TrustCom | 2 |
| 2013 | Research of Intrusion Detection System on AndroidabstractIn this paper, we proposed an intrusion detection system for detecting anomaly on Android smartphones. The intrusion detection system continuously monitors and collects the information of smartphone under normal conditions and attack state. It extracts various features obtained from the Android system, such as the network traffic of smartphones, battery consumption, CPU usage, the amount of running processes and so on. Then, it applies Bayes Classifying Algorithm to determine whether there is an invasion. In order to further analyze the Android system abnormalities and locate malicious software, along with system state monitoring the intrusion detection system monitors the process and network flow of the smartphone. Finally, experiments on the system which was designed in this paper have been carried out. Empirical results suggest that the proposed intrusion detection system is effective in detecting anomaly on Android smartphones. Fangfang Yuan, Lidong Zhai, Yanan Cao 0001, Li Guo 0001 |
SERVICES | 2 |
| 2011 | A Word Position-Related LDA ModelabstractLDA (Latent Dirichlet Allocation) proposed by Blei is a generative probabilistic model of a corpus, where documents are represented as random mixtures over latent topics, and each topic is characterized by a distribution over words, but not the attributes of word positions of every document in the corpus. In this paper, a Word Position-Related LDA Model is proposed taking into account the attributes of word positions of every document in the corpus, where each word is characterized by a distribution over word positions. At the same time, the precision of the topic-word's interpretability is improved by integrating the distribution of the word-position and the appropriate word degree, taking into account the different word degree in the different word positions. Finally, a new method, a size-aware word intrusion method is proposed to improve the ability of the topic-word's interpretability. Experimental results on the NIPS corpus show that the Word Position-Related LDA Model can improve the precision of the topic-word's interpretability. And the average improvement of the precision in the topic-word's interpretability is about 9.67%. Also, the size-aware word intrusion method can interpret the topic-word's semantic information more comprehensively and more effectively through comparing the different experimental data. Lidong Zhai, Zhaoyun Ding, Yan Jia 0001, Bin Zhou 0004 |
Int. J. Pattern Recognit. Artif. Intell. | 1 |